FatalRAT is a Windows remote access trojan written in C++ and associated with multiple Chinese-speaking intrusion and crimeware ecosystems, including activity linked to Purple Fox and campaigns assessed as China-nexus targeting organizations in the Asia-Pacific region. It has been observed in continuously updated variants and is often deployed as part of multi-stage infection chains rather than as a standalone initial payload.
FatalRAT provides remote command execution and system control, establishes command-and-control communications, fingerprints infected hosts, and can exfiltrate sensitive information. Reported variants load auxiliary modules conditionally based on victim-environment checks such as the presence of antivirus software or other host characteristics, allowing operators to tailor post-compromise behavior. Documented overlaps with older malware clusters indicate code reuse and shared tradecraft, including functionality associated with keylogging and broader surveillance-oriented collection.
Observed delivery has included trojanized software installers masquerading as legitimate applications, poisoned search-engine results leading users to fake downloads, phishing campaigns, and DLL sideloading. In Purple Fox-linked activity, malicious installers acted as first-stage loaders that retrieved second-stage archives and memory-loaded a FatalRAT-derived payload using custom shellcode loaders designed to minimize forensic artifacts. Some campaigns also paired FatalRAT with signed kernel drivers, rootkit components, and antivirus-evasion modules to disable or bypass security controls.
FatalRAT activity has targeted Chinese-language users in Southeast and East Asia as well as government and corporate networks in APAC. It has also been associated with lateral movement behavior in some reporting, including brute-force attempts against network shares and remote propagation after successful authentication. The malware is best characterized as a modular RAT used for persistent remote access, data theft, and follow-on intrusion activity on compromised Windows systems.
Mallory pivots from this family to the IOCs, detections, and named campaigns that touch your stack, and pages you when something new lands.
1 distinct threat actor attributed by public researchers. Open in Mallory to see the full evidence chain and overlapping campaigns.
45.192.219.135 — a Hong Kong VPS on Antbox Networks Limited (AS138995) that plays double duty as: FatalRAT C2 backend — tied to a live campaign deploying FatalRAT, Winos4.0, and QQHong sideloaded via Sogou Input Method DLL sideloading (ManualNewWord.dll), VMProtect-packed, beaconing on port 1080 + HTTPS cover on 443...
24 distinct techniques documented for this family, organized by ATT&CK tactic.
Chinese-language speakers in Southeast and East Asia were targeted with poisoned Google search results for popular applications such as the Firefox web browser, and popular messaging apps Telegram and WhatsApp, to install trojanized versions containing the FatalRAT remote access trojan.
FatalRAT is a C++-based implant designed to run commands and exfiltrate sensitive information back to a remote server.
After the shellcode loads and allocates memory for loading the stuffed PE modules inside svchost.txt, the execution flow will call into the first PE module found after the shellcode.
The installers are actively distributed online to trick users and increase the overall botnet infrastructure.
Users' machines are targeted via trojanized software packages masquerading as legitimate application installers.
The malware allowed for attackers to run tests that checked for virtual machines within the system before executing commands to infect the system remotely.
the Purple Fox group implements a customized user-mode shellcode loader that leaves little traces for cybersecurity forensics. It minimizes both the quantity and quality of the forensic evidence as the execution doesn’t rely on the native loader and doesn't respect the PE format for a successful execution.
It also initiates a second stage C&C channel with another set of servers. It sends all the fingerprinting logs collected from the victim’s system and then waits for new commands from the C&C server.
These packages act as a first-stage loader, triggering an infection sequence that leads to the deployment of a second-stage payload from a remote server.
24 indicators attributed across vendor reports, sandbox runs, and researcher write-ups. Full values are available in Mallory.
IPs, domains, and DNS infrastructure linked to this family.
File hashes (MD5, SHA-1, SHA-256) from samples and reports.
11 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.
Related coverage Cryptocurrency Users Targeted in Sophisticated ‘FatalRAT’ Phishing Campaign
FatalRAT1
Remote access trojan/backdoor used in a live campaign with DLL sideloading via Sogou Input Method, VMProtect packing, C2 over port 1080 with HTTPS cover on 443, and persistence via registry Run keys and scheduled tasks.
Known RAT delivered via phishing against APAC industrial organizations; uses legitimate Chinese cloud services as part of infrastructure.
Match every observed IP, domain, and hash against your live telemetry.
Named campaigns wielding this family, with evidence pinned to each claim.
CVEs this family uses for access and lateral movement.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Every documented technique, ranked by evidence weight.
Reddit, Mastodon, and CTI community discussion around this family.